CVE-2026-24401: avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response
containing a recursive CNAME record (bsc#1257235).
Affected Packages(13 packages)
avahi
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Fixed in:
0.6.32-32.39.1
avahi-compat-howl-devel
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Fixed in:
0.6.32-32.39.1
avahi-compat-mDNSResponder-devel
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Fixed in:
0.6.32-32.39.1
avahi-lang
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Fixed in:
0.6.32-32.39.1
avahi-utils
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Fixed in:
0.6.32-32.39.1
libavahi-client3
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Fixed in:
0.6.32-32.39.1
libavahi-client3-32bit
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Fixed in:
0.6.32-32.39.1
libavahi-common3
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Fixed in:
0.6.32-32.39.1
libavahi-common3-32bit
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Fixed in:
0.6.32-32.39.1
libavahi-core7
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5